The MIT license and Composer tooling make integration straightforward. The small project footprint keeps adoption simple, but its operational safeguards are not as strong as its stable version suggests.
58%
Total Score
67
100
93
50
The package has five releases since July 2023, but none in the last 12 months; the latest release was in December 2024, indicating a meaningful maintenance gap.
The repository recorded zero commits and zero active maintainers in the last three months, weakening evidence of ongoing maintenance.
There was no new or closed issue or pull-request activity in the last month, while one issue and one pull request remain open; this is a modest sign of limited project activity.
The repository has no published security policy, leaving reporting and response expectations undocumented.
All five analyzed action uses are unpinned, and the audit found a high-confidence unsound condition; there are no untrusted checkouts or script-injection findings, so this is a workflow-hygiene concern rather than a severe dependency risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^5.4 || ^6.4 || ^7.0 | — | — |
contao/core-bundle Version ^4.13 || ^5.3 | — | — |
symfony/http-kernel Version ^5.4 || ^6.4 || ^7.0 | — | — |
symfony/http-foundation Version ^5.4 || ^6.4 || ^7.0 | — | — |
symfony/dependency-injection Version ^5.4 || ^6.4 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.